Full control over where your data goes.

Enterprise security by design

EU hosting
Claude runs in AWS Bedrock in Ireland through the gateway, on the Business tier or higher with managed credits, priced above US list.
UK hosting
Available as deployed for the customer.
One gateway
Every prompt, connector and tool call goes through one audited path.
Reviewed before it runs
Every connector and skill is scanned before approval, and a critical finding blocks it until an owner overrides with a reason on the record.
Isolated execution
Hosted connectors and agent workspaces run in sandboxes off the laptop, and upstream tokens never leave Harriet’s servers.
Never trained on
LLM providers are contractually barred from training on your data.
One policy, every model
Any model, from GPT, Gemini and Claude to open-source models, behind one gateway, with the region and models each team may use decided by you.
Retention
Provider retention follows that provider’s terms, and tool-call payload capture is off by default.
Encryption
In transit over TLS, and at rest where applicable.

Model usage and BYOK

Your keys or ours
Bring your own keys for OpenAI, Anthropic and Google, or use Harriet managed credits, with the same per-team visibility either way.
Unified API
Claude, GPT, Gemini and open models behind a single endpoint, with the same policy and audit on every call.

Governance and admin controls

Identity
Okta OIDC with SCIM 2.0 provisioning, SSO-only mode, and two-step sign-in the organization can mandate.
Sign-in options
Slack, Microsoft and Google sign-in, magic links, and TOTP two-step the organization can mandate.
Profiles
Profiles decide which apps, skills and models each job can use, with a per-device model allowlist enforced on Harriet Desktop.
Tools
Enable per tool, restrict by role and group, and require human confirmation before a tool runs.
Bulk syncs
New tools default to disabled when a sync finds 50 or more.
Sub-processors
A live list, with 30 days’ notice before any change. See the list

Audit

Log
An append-only, exportable record of person, device, skill, connector, tool, outcome and upstream status.
Search
Filter by skill, user, date and traffic type, with every row deep-linkable.
Retention
Configurable, with a minimum of seven days.

Legal documents

Trusted by leading organizations

What compliance asks first.

Is our data used to train AI models?

No. Customer data is never used to train a Harriet model, and every LLM provider Harriet uses is contractually barred from training on it.

Where is our data processed?

Model calls can be pinned to the EU per team, and the live sub-processor list shows where each provider runs and under which transfer mechanism.

Can we bring our own API keys?

Yes. Bring your own keys for OpenAI, Anthropic and Google and keep your provider contracts, or use Harriet managed credits. Both give the same per-team visibility.

What happens before a connector or skill can run?

It is scanned and banded on submission. A critical finding blocks approval until an owner overrides it, with a reason on the record.

Which certifications does Harriet hold?

SOC 2 Type II, with the current report on the Trust Center, and a GDPR Data Processing Addendum with EU and UK transfer safeguards.

How do we control who can use what?

Profiles decide which apps, skills and models each job can use, and Okta OIDC with SCIM provisioning keeps that in step with your directory.

What happens to our data if we leave?

Customer data is deleted by default within 30 days of contract termination, unless the law requires otherwise.

Book a demo of Harriet.

Bring your security review. We will walk through it with the files your reviewer asks for.